About the role
Job Description
* Monitor and investigate potential security threats using tools such as Kibana/OpenSearch and Snowflake. * Analyze security logs and investigate suspicious or unusual activity, including spikes in traffic, unexpected changes in attack patterns, and new or disappearing attack signals. * Determine whether detected activity is malicious or benign and identify the appropriate response, including detection engineering to block malicious activity when needed. * Develop, tune, and deploy detection rules based on traffic behavior, HTTP request attributes, headers, device fingerprints, and other indicators to mitigate malicious activity. * Monitor existing detections and known attack patterns to make sure they continue to work as expected and identify any unusual changes in volume, sources, IPs, domains, or other indicators. * Support customer onboarding by analyzing web application traffic flows and configuring baseline detection and protection rules. * Investigate customer-reported incidents and missed detections, analyze attack traffic, and implement mitigations to improve protection coverage. * Document newly discovered threats and attacks, including evidence, findings, and indicators. * Communicate findings to Engineering and other stakeholders and provide the necessary technical details to support remediation and improvements to detection and protection mechanisms. * Partner directly with counterparts through a ticketing system and support portal to investigate issues, provide updates, and resolve security-related requests.
Qualifications
* 3–5 years of experience in Cybersecurity, Threat Research, or Threat Intelligence * Bachelor’s degree in Computer Science, Cybersecurity, Information Security, or a related field * Strong understanding of web technologies and networking fundamentals, including HTTP/HTTPS, TCP/IP, DNS, authentication, cookies, and browser-server interactions * Experience in web security research, bot management, fraud detection, or related domains * Hands-on experience with threat investigations, IOC analysis, and threat intelligence research * Experience with log analysis and investigation platforms such as Kibana/OpenSearch, Snowflake, Datadog, or similar tools * Strong SQL skills, including working with large datasets and UDFs * Basic knowledge of JavaScript for web and client-side analysis * Strong analytical and problem-solving skills * Ability to work independently and manage investigations with minimal supervision * Strong communication and collaboration skills * Passion for cybersecurity and continuous learning
NICE TO HAVE:
* Knowledge of MITRE ATT&CK, malware analysis, vulnerabilities, and adversary TTPs * OSINT and cyber threat intelligence research experience * Python and Jupyter Notebook experience for investigations and automation * Experience with GitHub and version control workflows